Re: .inc files
| From: | Charles Killian | Date: | Tue, 03 Oct 2000 09:37:32 +0000 |
| Subject: | Re: .inc files | ||
| References: | 1 2 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-18393@lists.php.net to get a copy of this message | ||
There are a couple of ways:
1. Rename to .php so PHP parses the files
2. Make the .inc file type parsed by PHP by adding .inc as a mime type
(AddType application/x-httpd-php .inc)
3. Move the .inc files out of the www tree so you can't point your browser
at them
4. Disallow serving up of .inc files with an apache Deny directive
Number 3, IMHO, is the best way to solve your problem.
Charles
----- Original Message -----
From: "Abe Asghar" <abe@fish.tm>
To: <php-general@lists.php.net>
Sent: Tuesday, October 03, 2000 2:30 AM
Subject: [PHP] .inc files
Hi Guys,
I am using a separate .inc file for the navigation on my website. However
if someone goes to the browser and types 'whatever'.inc - they get a listing
of all the PHP include file-
The page works fine but this gaping security hole gave me a bit of a shock -
Anyone know how to get around it?
Thanks,
Abe
--
PHP General Mailing List (http://www.php.net/)
To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net
For additional commands, e-mail: php-general-help@lists.php.net
To contact the list administrators, e-mail: php-list-admin@lists.php.net